UNCLASSIFIED
4.3.2
Responsibilities of Information Risk Owner
The security organisation shall appoint a Board-level official to the role of
Information Risk Owner (IRO) with responsibilities including:
4.3.2.1
Ownership of a plan to foster a culture of information security;
Accountability for the organisational risk management policy;
Alignment of the risk management programme with business processes;
Advising on information risk sections of the Statement on Internal Control;
Ensuring that all assets have skilled and empowered owners; and
The production of quarterly and annual information risk assessments.
Choice of Information Risk Owner
It is important to stress that the IRO is a role not necessarily a job title. As such,
organisations could appoint anyone with adequate standing and expertise to this
role. However, guided by the Presidential Directive to create a programme to
professionalise information security, the Chief Information Security Officer
(CISO) or a similar title must be the first choice for the Board-level IRO role.
Choosing a CISO for the IRO role would help ensure that the Board receives
timely and effective advice about the impacts of their strategic and operational
decisions on information security. Organisations may appoint an interim IRO
during the hiring and/or training of a CISO or similar title to take over the role.
4.3.3
Responsibilities of Information Asset Owners
Information asset owners must be heads of division or department and perform
the following functions:
4.3.4
Understand and support the organisation’s security culture;
Know what information the assets under their responsibility hold;
Know who accesses the assets under their responsibility and why;
Identify and mitigate risks to the assets under their responsibility;
Ensure that assets under their responsibility are available for business use;
Provide the Board-level Information Risk Owner reasonable assurance that
the assets under their responsibility are secure at least annually.
Responsibilities of Security Coordination Group
Led by Board-level Information Risk Owner, the information security coordinators
must perform the following functions:
Ensure that effective information risk management processes are in place;
15